Cur1Downloader

First seen
2021-05-15 00:00:00
Malware type
downloader
Profile updated
2026-07-07 14:37:43

Targeted industries: financial-services government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:kr country_code:us country_code:jp

Context

Cur1Downloader is a downloader linked to the Lazarus group, potentially targeting sectors in South Korea, the United States, and Japan. It is used to download additional payloads onto compromised systems.

Reports & references

  • blogs.jpcert.or.jp — Dangerouspassword (report)
  • mp.weixin.qq.com — Nnlqubpx8Xz3Hcr5U Isjq (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Cur1 Downloader (report)
  • Kaspersky — 108383 (report)
  • twitter.com — 1595365451495706624 (report)

External references